[2023] 312-49v10 Actual Exam Dumps, 312-49v10 Practice Test [Q362-Q381]

Share

[2023] 312-49v10 Actual Exam Dumps, 312-49v10 Practice Test

DumpsValid 312-49v10 dumps & CHFI v10 sure practice dumps


EC-COUNCIL 312-49v10 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Defeating Anti-Forensics Techniques
  • Malware Forensics
Topic 2
  • Database Forensics
  • Network Forensics
  • Windows Forensics
Topic 3
  • Computer Forensics in Today’s World
  • Investigating Web Attacks

 

NEW QUESTION 362
To make sure the evidence you recover and analyze with computer forensics software can be admitted in court, you must test and validate the software. What group is actively providing tools and creating procedures for testing and validating computer forensics software?

  • A. Society for Valid Forensics Tools and Testing (SVFTT)
  • B. Computer Forensics Tools and Validation Committee (CFTVC)
  • C. National Institute of Standards and Technology (NIST)
  • D. Association of Computer Forensics Software Manufactures (ACFSM)

Answer: C

 

NEW QUESTION 363
When obtaining a warrant, it is important to:

  • A. generallydescribe the place to be searched and particularly describe the items to be seized
  • B. particularlydescribe the place to be searched and generally describe the items to be seized
  • C. particularlydescribe the place to be searched and particularly describe the items to be seized
  • D. generallydescribe the place to be searched and generally describe the items to be seized

Answer: C

 

NEW QUESTION 364
The ____________________ refers to handing over the results of private investigations to the authorities because of indications of criminal activity.

  • A. Kelly Policy
  • B. Locard Exchange Principle
  • C. Silver-Platter Doctrine
  • D. Clark Standard

Answer: C

 

NEW QUESTION 365
Which federal computer crime law specifically refers to fraud and related activity in connection with access devices like routers?

  • A. 18 U.S.C. 1362
  • B. 18 U.S.C. 2511
  • C. 18 U.S.C. 2703
  • D. 18 U.S.C. 1029

Answer: D

 

NEW QUESTION 366
From the following spam mail header, identify the host IP that sent this spam?
From [email protected] [email protected] Tue Nov 27 17:27:11 2001 Received: from viruswall.ie.cuhk.edu.hk (viruswall [137.189.96.52]) by eng.ie.cuhk.edu.hk (8.11.6/8.11.6) with ESMTP id fAR9RAP23061 for ; Tue, 27 Nov 2001 17:27:10 +0800 (HKT) Received: from mydomain.com (pcd249020.netvigator.com [203.218.39.20]) by viruswall.ie.cuhk.edu.hk (8.12.1/8.12.1) with SMTP id fAR9QXwZ018431 for ; Tue, 27 Nov 2001 17:26:36 +0800 (HKT) Message-Id: >[email protected] From: "china hotel web" To: "Shlam" Subject: SHANGHAI (HILTON HOTEL) PACKAGE Date: Tue, 27 Nov 2001 17:25:58 +0800 MIME-Version: 1.0 X-Priority: 3 X-MSMail- Priority: Normal Reply-To: "china hotel web"

  • A. 8.12.1.0
  • B. 203.218.39.50
  • C. 203.218.39.20
  • D. 137.189.96.52

Answer: C

 

NEW QUESTION 367
Which US law does the interstate or international transportation and receiving of child pornography fall under?

  • A. §18. U.S.C 2252
  • B. §18. U.S.C 146A
  • C. §18. U.S.C 252
  • D. §18. U.S.C. 1466A

Answer: A

 

NEW QUESTION 368
Which of the following are small pieces of data sent from a website and stored on the user's computer by the user's web browser to track, validate, and maintain specific user information?

  • A. Web Browser Cache
  • B. Temporary Files
  • C. Open files
  • D. Cookies

Answer: D

 

NEW QUESTION 369
Which of the following tool is used to locate IP addresses?

  • A. SmartWhois
  • B. Towelroot
  • C. Deep Log Analyzer
  • D. XRY LOGICAL

Answer: A

 

NEW QUESTION 370
Casey has acquired data from a hard disk in an open source acquisition format that allows her to generate compressed or uncompressed image files. What format did she use?

  • A. Advanced Forensics Format (AFF)
  • B. Raw Format
  • C. Portable Document Format
  • D. Proprietary Format

Answer: A

 

NEW QUESTION 371
Pagefile.sys is a virtual memory file used to expand the physical memory of a computer. Select the registry path for the page file:

  • A. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
  • B. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
  • C. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\System Management
  • D. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Device Management

Answer: A

 

NEW QUESTION 372
Which code does the FAT file system use to mark the file as deleted?

  • A. ESH
  • B. E5H
  • C. H5E
  • D. 5EH

Answer: B

 

NEW QUESTION 373
What happens lo the header of the file once It Is deleted from the Windows OS file systems?

  • A. The OS replaces the second letter of a deleted file name with a hex byte code: Eh5
  • B. The OS replaces the first letter of a deleted file name with a hex byte code: E5h
  • C. The OS replaces the entire hex byte coding of the file.
  • D. The hex byte coding of the file remains the same, but the file location differs

Answer: B

 

NEW QUESTION 374
Richard is extracting volatile data from a system and uses the command doskey/history. What is he trying to extract?

  • A. Previously typed commands
  • B. Passwords used across the system
  • C. History of the browser
  • D. Events history

Answer: A

 

NEW QUESTION 375
Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company's network. Since Simon remembers some of the server names, he attempts to run the axfr and ixfr commands using DIG. What is Simon trying to accomplish here?

  • A. Enumerate all the users in the domain
  • B. Perform DNS poisoning
  • C. Send DOS commands to crash the DNS servers
  • D. Perform a zone transfer

Answer: D

 

NEW QUESTION 376
When investigating a Windows System, it is important to view the contents of the page or swap file because:

  • A. This is the file that windows use to store the history of the last 100 commands that were run from the command line
  • B. This is file that windows use to communicate directly with Registry
  • C. Windows stores all of the systems configuration information in this file
  • D. A Large volume of data can exist within the swap file of which the computer user has no knowledge

Answer: D

 

NEW QUESTION 377
Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reaching the incident scene, Chris secures the physical area, records the scene using visual medi a. He shuts the system down by pulling the power plug so that he does not disturb the system in any way. He labels all cables and connectors prior to disconnecting any. What do you think would be the next sequence of events?

  • A. Connect the target media; Prepare the system for acquisition; Secure the evidence; Copy the media
  • B. Secure the evidence; prepare the system for acquisition; Connect the target media; copy the media
  • C. Connect the target media; prepare the system for acquisition; Secure the evidence; Copy the media
  • D. Prepare the system for acquisition; Connect the target media; copy the media; Secure the evidence

Answer: D

 

NEW QUESTION 378
Which of the following stages in a Linux boot process involve initialization of the system's hardware?

  • A. BIOS Stage
  • B. BootROM Stage
  • C. Bootloader Stage
  • D. Kernel Stage

Answer: A

 

NEW QUESTION 379
What does Locard's Exchange Principle state?

  • A. Anyone or anything, entering a crime scene takes something of the scene with them, and leaves something of themselves behind when they leave
  • B. Any information of probative value that is either stored or transmitted in a digital form
  • C. Forensic investigators face many challenges during forensics investigation of a digital crime, such as extracting, preserving, and analyzing the digital evidence
  • D. Digital evidence must have some characteristics to be disclosed in the court of law

Answer: A

 

NEW QUESTION 380
One technique for hiding information is to change the file extension from the correct one to the one that might not be noticed by an investigator. For example, changing a .jpg extension to a .doc extension so that a picture file appears to be a document. What can an investigator examine to verify that a file has the correct extension?

  • A. The File Allocation Table
  • B. The sector map
  • C. The file header
  • D. The file footer

Answer: C

 

NEW QUESTION 381
......

312-49v10 Actual Questions and Braindumps: https://testprep.dumpsvalid.com/312-49v10-brain-dumps.html